Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed810259554df223…

MALICIOUS

PDF

23.7 KB Created: 2019-05-02 01:19:46 +01:00 Authoring application: mPDF 5.7
MD5: 9235864e9a4b340ac9187cb93ad89091 SHA-1: 261cb2e3df3258a67bafcdd4ffc75057b56c5b67 SHA-256: ed810259554df223207b2eb1a4564f570c2182687086e72afdf2d6d8bd36dba1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. While many of these links point to benign-looking book titles, the sheer volume and the use of a dynamic DNS hostname suggest a link farm intended for SEO manipulation or to distribute further malicious content. No scripts were extracted from this sample.

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2097092091091090/The-Invisible-Bond-How-to-Break-Free-from-Your-Sexual-Past-by-Barbara-Wilson.pdf
    • http://loaminoo.linkpc.net/1093095094096094/Erotic-Marriage-Break-Free-from-the-Negative-Sexual-Script-and-Improve-the-Sexual-and-Emotional-Quality-of-Your-Relationship-by-Frederick-D-Mondin.pdf
    • http://loaminoo.linkpc.net/1091097099097093/Once-You-Break-a-Knuckle-by-D-W-Wilson.pdf
    • http://loaminoo.linkpc.net/2098091096097096/Clean-Break-by-Jacqueline-Wilson.pdf
    • http://loaminoo.linkpc.net/2095092091095091/The-Sleeping-Serpent-A-Woman-s-Struggle-to-Break-an-Obsessive-Bond-With-Her-Yoga-Master-by-Luna-Saint-Claire.pdf
    • http://loaminoo.linkpc.net/1094096091099096/Break-Free-Smart-Girl-Mafia-1-by-Amiee-Smith.pdf
    • http://loaminoo.linkpc.net/9095096090090093/Low-Carb-So-Simple---Easy-Everyday-Recipes-with-5-Ingredients-or-Less-Gluten-Free-Sugar-Free-Grain-Free-Sweetener-Free-Wheat-Free-Grain-Free-by-Elviira-Krebber.pdf
    • http://loaminoo.linkpc.net/2095096095092096/Breaking-Fall-or-Break-2-by-Barbara-Elsborg.pdf
    • http://loaminoo.linkpc.net/4096099094099099/Falling-Fall-or-Break-1-by-Barbara-Elsborg.pdf
    • http://loaminoo.linkpc.net/2093098090090095/Complaints-amp-Disorders-The-Sexual-Politics-of-Sickness-by-Barbara-Ehrenreich.pdf
    • http://loaminoo.linkpc.net/3097095091099097/Past-Life-Tourism-by-Barbara-Ford-Hammond.pdf
    • http://loaminoo.linkpc.net/1091090092091096094/Set-Yourself-Free-Reon-Schuttes-10-Principles-to-Break-Out-of-Your-Personal-Prison-Through-the-Power-of-Choice-by-Reon-Schutte.pdf
    • http://loaminoo.linkpc.net/3095095099094092/The-Food-Babe-Way-Break-Free-from-the-Hidden-Toxins-in-Your-Food-and-Lose-Weight-Look-Years-Younger-and-Get-Healthy-in-Just-21-Days-by-Vani-Hari.pdf
    • http://loaminoo.linkpc.net/1099099096091/The-Dog-Collar-Murders-Pam-Nilsen-3-by-Barbara-Wilson.pdf
    • http://loaminoo.linkpc.net/1090095095098094/A-Free-Man-of-Color-Benjamin-January-1-by-Barbara-Hambly.pdf
    • http://loaminoo.linkpc.net/3099092099091090/Kicking-In-the-Wall-A-Year-of-Writing-Exercises-Prompts-and-Quotes-to-Help-You-Break-Through-Your-Blocks-and-Reach-Your-Writing-Goals-by-Barbara-Abercrombie.pdf
    • http://loaminoo.linkpc.net/9094096096093098/Home-Enlightenment-Practical-Earth-Friendly-Advice-for-Creating-a-Nurturing-Healthy-and-Toxin-Free-Home-and-Lifestyle-by-Annie-Berthold-Bond.pdf
    • http://loaminoo.linkpc.net/4093091093091096/If-I-Break-Complete-Series-If-I-Break-1-3-by-Portia-Moore.pdf
    • http://loaminoo.linkpc.net/7092096093093092/The-Sexual-Teachings-of-the-Jade-Dragon-Taoist-Methods-for-Male-Sexual-Revitalization-by-Hsi-Lai.pdf
    • http://loaminoo.linkpc.net/4099090091099090/Break-Me-Make-or-Break-2-by-Amanda-Heath.pdf
    • http://loaminoo.linkpc.net/9095096090090093/Low-Carb-So-Simple--